CVE-2020-15217: GLPI-Project GLPI

Medium severity, CVSS 5.3. EPSS: 1% chance of exploitation in the next 30 days.

In GLPI before version 9.5.2, there is a leakage of user information through the public FAQ. The issue was introduced in version 9.5.0 and patched in 9.5.2. As a workaround, disable public access to the FAQ.

Affected products

  • GLPI-Project GLPI: from 9.5.0, before 9.5.2 (fixed in 9.5.2)

Published 2020-10-07. Last modified 2026-06-17.